
GitHub has introduced repository-level configuration options for Dependabot runners, allowing administrators to specify runner types, custom labels, and runner groups for version and security updates. This feature extends existing organization-level controls, enabling teams to direct Dependabot jobs to self-hosted runners with access to private package registries or specialized environments. The setting is available for private and internal repositories on github.com but remains hidden for public repositories and GitHub Enterprise Server. Security configurations do not currently enforce these runner settings.
Read original
© GitHub ChangelogGitHub finally bridges the gap between code and corporate governance with external custom properties. By allowing systems like CMDBs to push read-only metadata—ownership, compliance status, service tiers—directly into repos, it stops developers from manually tagging repositories in silos. The real win is the dedicated namespace and strict read-only enforcement, which prevents data conflicts between GitHub’s UI and your internal source of truth. This turns repository filtering and ruleset targeting into dynamic, business-aware operations rather than static code-level checks.
© GitHub ChangelogAnthropic quietly upgrades its local coding agent with Sonnet 5.5 as the new default, bringing a massive 1M context window to developers' terminals. This isn't just a model swap; it fundamentally changes how much codebase history you can keep in memory without manual chunking. The release also patches critical stability issues like malformed image crashes and broken MCP reconnections, making the tool significantly more reliable for complex workflows. For builders, this means deeper context awareness and fewer interruptions during long coding sessions.
This release prioritizes security hygiene and session reliability over new features. The addition of CLAUDE_CODE_DISABLE_WEB_FETCH is a critical control for enterprise environments needing to restrict external data access. Bug fixes address subtle race conditions in cloud sessions and artifact publishing that could lead to data loss or incorrect state. SSH and plugin installation issues are resolved, ensuring smoother remote workflows. It’s a maintenance update that tightens the tool's operational boundaries.
OpenAI’s GPT-6.1 Sol is now live in GitHub Copilot, targeting the sweet spot between raw power and cost efficiency. Early testing shows it completes multi-step coding tasks with significantly fewer tokens and steps than previous GPT-6 or GPT-5.6 models. This isn't just a version bump; it’s a direct response to developer fatigue over token burn rates during complex agentic workflows. Available across all major IDEs and the Copilot CLI, it shifts the baseline for what constitutes an efficient coding agent. The real win here is the reduction in friction for long-running terminal tasks.